republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » What is 67.72.4.94?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
KAV classifies mIRC as Riskware? »
« Spybot caught Resellerratings trying to install...  
AuthorAll Replies

TheWiseGuy
Dog And Butterfly
Premium,MVM
join:2002-07-04
Yonkers, NY


1 edit
reply to Spooler
Checking Automatic Update

OK had some time to do a couple of tests and check some tools.

You can try turning off automatic update, and then turning it back on, this should cause it to check for updates and may tell you if it is what is causing the connection. When I did this several times, Port Reporter recorded svchost connecting each time to three IPs, in one of the updates the last was a Footprint Server on the Level 3 network.
64.152.17.157

If that doesn't confirm it, you can install and run Port Reporter it may provide enough information to figure it out.

»support.microsoft.com/default.as···d=837243
--
Dog and Butterfly


Spooler

@cableone.net

ID Serve & Checking Automatic Update

Well, thanks again, Dr. S & WiseGuy:

Went to GRC and downloaded ID serve as suggested. It clearly confirms the ID of the IP in Question as a "Footprint" site.
(see above) Thanks for that tool.

Also turned AutoUpdates off & back on and rebooted.

Computer went to home page first (Yahoo), then to ZA sites, Perhaps AutoUpdates was using Akamai that time rather than Level 3.then to 81.52.249.182 which is identified as an Akamai site.

TCPview showed that site and "System"0 for a while then it disappeared from view.

Raises a new issue though, and that is:
What is the Process reported as "System 0" in TCPview where it normally reports the Service and PID?

TheWiseGuy
Dog And Butterfly
Premium,MVM
join:2002-07-04
Yonkers, NY

said by Spooler:

Also turned AutoUpdates off & back on and rebooted.
I didn't need to reboot, I hit apply (WinXP Home) and it immediately checked for Updates, disabled it, waited a couple of minutes and selected "Notify me but..." again and it connected out again.

I believe PID 0 is normally System Idle process.
--
Dog and Butterfly


BlitzenZeus
Burnt Out Cynic
Premium,MVM
join:2000-01-13
Beaverton, OR
PID 0 is actually a port waiting to timeout for its next use, the program that was listening is no longer bound to that port, and these are just past connections, however they do not show which program was listening.


Spooler

@cableone.net

WiseGuy and Zeus:

Thanks again. Sorry this turned into such a long dialog, but each post resulted in new learning (for me, at least).
----------------
Wise Guy:

I turned Windows Updates off and on without rebooting as you suggested. Kept TCPview on top to see what happened in real time. Three IP's appeared:

Two to MSFT at 64.4.23.156 which is ID'd as v5.windowsupdate.microsoft.com in my router logs.

And then one to 67.72.120.62 which is ID'd as "Footprint Distributor" by the GRC ID Serve utility you suggested.

That's a neat little tool. Thanks for recommending it.
--------------

BlitzenZeus:

Once again, you are right on from the start.

The exercises since your first post confirm the outbound to IP 67.72.4.94 is connected to MSFT Windows AutoUpdates using Level Three and what turned the third party servers - "Footprint".

TCPview caught it in action just as you said it would.

Thanks Everyone.
------------------

Mods - looks like we are done here with this one.

bthielen

join:2004-11-15

Check out
»headers.bragger.net/info/footpri···tor.html

Leads to sandpiper.net then this..
»www.cw.com/about_us/company_prof···_7a.html
Forums » Up and Running » Security » SecurityKAV classifies mIRC as Riskware? »
« Spybot caught Resellerratings trying to install...  


Monday, 09-Nov 15:57:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [52] VoIP Over 3G Still Not Working For iPhone
· [28] Verizon Keeps Swinging At AT&T
· [26] Bill Would Force ISPs To Block Financial Scams
· [14] Mediacom Hints At 50, 100 Mbps Speeds
· [10] Clearwire To Get Another $1.5 Billion
· [8] 15 States Have Now Gotten Broadband Mapping Money
Most people now reading
· Divorce advice... [General Questions]
· 60 Minutes piece on cyber security last night [Security]
· My cat is reluctant to exercise. [General Questions]
· How in the world am I going to get into college? [General Questions]
· Framed for child porn 151; by a PC virus [Security]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· A fishy CRTC tarriff filed by bell? [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]